← Blog

CyrusOne Claim: ShinyHunters Demands $13M

Share on X

Unverified claim: On 23 August 2026, ShinyHunters updated a leak-site listing to name CyrusOne, LLC — a major US data-center operator whose customers have included names like Microsoft and Meta — and demanded roughly $13 million, claiming about 12.9 million Salesforce records plus SharePoint archives and facility security files. CyrusOne had not publicly confirmed at indexing, and Cybernews reported no samples published with the listing. Canonical: cyrusone-shinyhunters2026. Reporting: Cybernews.

This is not a routine CRM dump story. If the actor inventory is even partly real, the sensitive bits are not only contact rows — they are alleged floor plans, electrical diagrams, badge audits, physical key inventories, and critical-environment reliability docs. Passwords rotate in hours. Re-keying cages does not.

What ShinyHunters claimed in the CyrusOne listing

Cybernews reconstructed the timeline from the leak site. On 20 August the group posted a redacted “FINAL WARNING PAY OR LEAK” entry with an end-of-24 August contact deadline. On 23 August the victim name flipped to CyrusOne, LLC, the ransom figure landed near $13 million, and the post listed an inventory that included:

  • About 12.9 million Salesforce records (including a Contacts object count in the low hundreds of thousands)
  • Roughly 370GB compressed SharePoint (actor estimate ~645GB uncompressed)
  • More than 8,300 employee PII rows
  • Contracts, MSAs, NDAs, and service agreements
  • Data-center floor plans and electrical diagrams
  • Access-control records, badge audits, physical key inventories, security policies
  • Password lists and other credential artifacts
  • Critical Environment Reliability Management documentation

BreachHistory indexes recordsAffected 12900000 from the actor’s Salesforce headline — labeled unverified — and companyConfirmed false until CyrusOne or a regulator attests.

Why a data-center operator listing is different

Most ShinyHunters Salesforce stories hurt because attackers get emails and titles for spear-phishing. A colocation operator listing, if authentic, adds a physical layer. Cybernews researchers put it bluntly: floor plans and camera placement show where cages, mantraps, and doors sit; badge audits hint who can walk where; power and cooling docs can read like “a guide to causing an outage” even when they do not grant remote control.

Tenants are exposed to second-order risk without having been breached themselves. Contracts and rack-adjacent paperwork can become a customer list drawn on a building map — perfect raw material for fake change-window tickets and fake NOC calls.

What this is not (yet)

To be clear: Cybernews said attackers had not published samples at the time of their report, and CyrusOne had not issued a public confirmation. That combination means you should treat the $13 million demand and the 12.9 million figure as extortion marketing until primary evidence arrives. ReliaQuest’s August ShinyHunters episode is a reminder that leak-site theater can outrun actual access.

Who should care

CyrusOne employees and contractors — if the 8,300-row employee claim is real, expect phishing that cites badge numbers and shift patterns.

Colocation and wholesale tenants — especially Fortune-scale names historically associated with the operator. Assume attackers may try to sound like account managers who know your SLA and cage ID.

Physical security and critical-environment teams — treat alleged layout and CERM documents as high-sensitivity even before forensic confirmation.

Campaign context

Summer 2026 ShinyHunters listings repeatedly marketed Salesforce-scale hauls against enterprises and healthcare brands — Questel, Lumenis, Alcon, Brinks Home, and others already sit in this catalog. CyrusOne sits in a different risk class because the claimed artifacts mix CRM scale with facility tradecraft. Do not merge this row with ReliaQuest’s confirmed view-only Okta incident; different victim, different evidence bar.

Action items

  1. Bookmark official CyrusOne security/status channels; ignore “pay or we publish floor plans” emails.
  2. Tenants: verify any rack, badge, or change-window request out-of-band using a pre-agreed number — not a number in the email.
  3. Employees named in corporate directories: watch MFA fatigue and fake IT callbacks citing Salesforce case IDs.
  4. If you reuse passwords across work tools, rotate them; assume credential artifacts may be in actor inventories even when samples are absent.
  5. Security teams: tabletop a “leak site names our colo operator” scenario — holding statement, tenant notification template, physical-security review — without waiting for samples.
  6. Do not download alleged “proof packs” from forums; wait for company or regulator notices.

Canonical record and sources

Catalog: cyrusone-shinyhunters2026 — unverified ShinyHunters extortion listing; recordsAffected 12900000 (actor Salesforce claim). Related ShinyHunters rows: ReliaQuest, Questel, Lumenis.

Primary trade source: Cybernews — CyrusOne / ShinyHunters.

Search coverage: CyrusOne data breach, CyrusOne ShinyHunters, data center floor plans leak, Salesforce records extortion, was I affected CyrusOne, colo phishing, critical infrastructure ransomware claim 2026.

Phishing after a named data-center claim usually arrives before any polished FAQ. Attackers need a headline, a floor plan rumor, and a few accurate badge titles — not your regulator’s timeline.

Facility diagrams and badge audits enable scams that cite your exact cage or loading-dock routine. Verify every “CyrusOne NOC” callback against a number you set before the headline.

Tenants should separate “operator listed on a leak site” from “your VM was exfiltrated.” The first is a supply-chain alert; the second needs evidence.

Journalists should keep “12.9 million Salesforce records” labeled as actor marketing until samples or company confirmation arrive. Collapsing them into a confirmed census produces false precision.

Secondary scams include fake “leak lookup” bots for rack maps, fake KKR/GIP investor portals, and monitoring signups that harvest more data than they protect.

If you forward breach news in work Slack, forward the Cybernews URL and the BreachHistory canonical link — not a forum sales screenshot of floor plans.

Physical security teams become social-engineering targets when layouts leak. Brief them early and rotate any shared contractor PINs.

International staff at hyperscale tenants should not assume “US only.” Personalized lures travel with the corporate email address.

Call-center and NOC staff should use out-of-band verification when a caller recites recent trivia about your cage or SLA. Accuracy is not authentication.

Expect copycat leak posts that paste the same victim name with inflated Salesforce counts. Check dates and primary URLs.

Legal teams drafting notices should wait for inventory rather than marketing every actor CSV as gospel.

Open bookmarks to official CyrusOne status and security contact channels now so you are not searching under panic later.

When samples appear in trade press, demand schema description without republishing identifiable floor plans or employee rows.

Partners reading this as a peer incident should tabletop: Sunday leak-site listing, same-day holding statement, and customer SMS without payment links.

The practical closing line: confirm via official channels, rotate reused passwords, and treat hyper-accurate facility outreach as hostile.

Merchants and SaaS vendors whose customers colocate at named operators still own the customer relationship — and the phishing blowback.

Rotate API keys and webhook secrets whenever a colocated CRM or SharePoint stack is named in a leak claim, even before confirmation.

ShinyHunters Salesforce campaigns often recycle the same playbook across unrelated verticals. Treat each listing as its own evidence problem.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.

BreachHistory revises rows when primary notices revise counts or confirm actor claims. Actor floors are scaffolding, not scripture — treat leak-site inventories as labeled claims until the victim or a regulator attests.